Browse Topic: Embedded software

Items (263)
As embedded electronic control systems are increasingly penetrating vehicle subsystems, the designers are faced with a dilemma of providing state of art vehicle features on one hand and ensuring frugal implementation of the same to meet competitive pressures on the other. For embedded software and hardware systems this means adoption of judicious and innovative design choices with reusable building blocks. This paper dwells upon various design aspects of control and monitoring which are frequently used for automotive applications such as feed-forward and proportional integral control, diagnostics for sensor boundary conditions, handling of intermittent faults without causing nuisance to the vehicle users etc.
Vaidya, Vishwas Manohar
This paper explains why software for efficient model-based development is needed to improve the efficiency of automakers and suppliers when implementing solutions with next generation automotive embedded systems. The resulting synergies are an important contribution for the automotive industry to develop safer, smarter, and more eco-friendly cars. To achieve this, it requires implementations of algorithms for machine learning, deep learning and model predictive control within embedded environments. The algorithms’ performance requirements often exceed the capabilities of traditional embedded systems with a homogeneous multicore architecture and, therefore, additional computing resources are introduced. The resulting embedded systems with heterogeneous computing architectures enable a next level of safe and secure real-time performance for innovative use cases in automotive applications such as domain controllers, e-mobility, and advanced driver assistance systems (ADAS). However, the increased system complexity challenges the efficiency of system verification during product development. The industry cannot afford delays in design cycles and efficient utilization of R&D resources is an important success factor. Model-based controls and software development with automatic code generation is an important dimension to resolve this challenge. It enables efficient algorithm development and verification and, thereby, supports to achieve ISO26262 compliance during product development. This is explained in this paper along three perspectives: Firstly, a use case overview explains the drivers for more advanced algorithms and, therefore, more high-performance computing resources. Secondly, a tool flow is proposed, which provides an efficient model-based controls and software development environment for next generation heterogeneous embedded systems. And lastly, this proposal is tested against automakers requirements for software and function development. Combining these perspectives sheds light on future automotive embedded software and systems, which experience an increasing relevance as demonstrated by recent automakers decisions to increasingly take ownership of software development.
Schaefer, JuergenChristlbauer, HerbertSchreiber, AlexanderReith, GrahamJonker, MischaPotman, JordyDannebaum, UdoEissfeldt, Tjark
One of the most significant barriers to adoption of Model-Based Systems Engineering (MBSE) (Ref. 1) and the Modular Open System Approach (MOSA) (Ref. 2) is a cost-effective and commonly understood process that combines the best of both. Such a process must earn its way as a replacement for traditional processes used for the development of embedded software. Most, if not all, developers of embedded flight software have development processes that have evolved over many years. This creates a situation in which the one-time expense of conversion to a new process can be cost prohibitive. As such, adoption of MBSE has been limited and compliance with the intent of MOSA statutory and regulatory requirements has been mainly conformance to an open standard. Systems can be built that are modular but not open. Modularity can be a desirable design objective for quality systems engineering (such as the separation of concerns or encapsulation of functionality) apart from the open systems qualities of portability, reusability, maintainability, and so forth. This results in adoption of closed practices in the use of modeling technology that can be (and often are) done in a monolithic way without regard to the many different tools used in a multi-vendor environment. This paper presents an outline and structure to avoid such pitfalls.
DuBois, ThomasStough, JohnLinden, DavidWalsh, DavidGoebel, ChristopherMatthews, Robert
Selftrust - A Practical Approach for Trust Establishment2020-01-07204/14/2020
In recent years, with increase in external connectivity (V2X, telematics, mobile projection, BYOD) the automobile is becoming a target of cyberattacks and intrusions. Any such intrusion reduces customer trust in connected cars and negatively impacts brand image (like the recent Jeep Cherokee hack). To protect against intrusion, several mechanisms are available. These range from a simple secure CAN to a specialized symbiote defense software. A few systems (e.g. V2X) implement detection of an intrusion (defined as a misbehaving entity). However, most of the mechanisms require a system-wide change which adds to the cost and negatively impacts the performance. In this paper, we are proposing a practical and scalable approach to intrusion detection. Some benefits of our approach include use of existing security mechanisms such as TrustZone® and watermarking with little or no impact on cost and performance. In addition, our approach is scalable and does not require any system-wide changes. To detect intrusions, we propose a combination of TrustZone® secure space approach along with a mechanism of static and dynamic watermarks. The current scope of research is restricted to architectures which provide a secure space to execute software. The research is an enhancement over the current TrustZone® implementation for device control post intrusion. In conclusion, the proposed approach is a simple and scalable mechanism for detection and control of intrusion.
Abhyankar, Ranjit VinayakA, Sreenath
This standard specifies the communications hardware and software requirements for fueling hydrogen surface vehicles (HSV), such as fuel cell vehicles, but may also be used where appropriate, with heavy-duty vehicles (e.g., busses) and industrial trucks (e.g., forklifts) with compressed hydrogen storage. It contains a description of the communications hardware and communications protocol that may be used to refuel the HSV. The intent of this standard is to enable harmonized development and implementation of the hydrogen fueling interfaces. This standard is intended to be used in conjunction with the hydrogen fueling protocols in SAE J2601 and nozzles and receptacles conforming with SAE J2600.
Fuel Cell Standards Committee
Design and Validation of a Prototype Underlying Control System for Autonomous Vehicles2019-01-506211/4/2019
With the development of self-driving cars, large amounts of sensors controllers, actuators and other devices will be integrated into autonomous driving system and the electrical and electronic architecture of traditional vehicles needs to be changed and upgraded. Therefore, this paper proposes a kind of autonomous vehicle underlying control system, which inputs perception and decision information and outputs control instructions to complete autonomous driving. The original vehicle electrical system hardware and software had redesigned and developed and a new electronic and electrical architecture for self-driving vehicles is presented. The underlying control system was designed to solve the problem of system integration and meet the upgrading requirements of data calculation and real-time transmission in autonomous vehicles. In the paper, the overall designing scheme of underlying control system introduces the underlying control system architecture diagram and three-layer modular communication architecture, then autonomous vehicles underlying control system hardware circuit design, software design and experiments are separated illustrated. With regards of hardware circuit, the underlying control system components, working mechanism and the integration with perception module and positioning module were designed and introduced. Moreover, with the consideration of data transmission and system reliability, the software architecture, data communication and control flow diagram were designed and explained. In addition, the control system performance and functional experiments were implemented to validate the underlying control system. Finally, it can be verified that the prototype underlying control system for autonomous vehicles not only had good steering, driving and braking characteristics, but also had a good performance in self-driving car tracking, stopping and dynamic path planning functions.
Wang, RongSong, JuanFeng, ShuojiZhang, Chaoyu
Model-Based Software Development: Functional Safety Compliance via Built-In Tool Intelligence2019-01-10414/2/2019
Today’s automobiles are among the most sophisticated machines on the planet. Much of the functionality of modern automobiles emanates from embedded software features that control electronic, mechanical or pneumatic devices. Over the past few decades the number of software features and the associated code has grown exponentially and the respective embedded software systems have reached a level of complexity which is increasingly difficult to manage. As a consequence, recalls due to software defects have become a major concern and today constitute about 50% of the overall warranty cost [1]. Since the operation of automobiles has severe public safety implications, the development of embedded automotive software has become subject to stringent functional safety standards (ISO 26262) and compliance with these standards has become a major hurdle in the development of automotive software. This paper outlines a tool-based solution that satisfies an important subset of functional safety standards via built-in intelligence. The solution marks a major step towards an agile, safety compliant development process that does not impose restrictions regarding product innovation. The core concept of this tool-based solution is centralized architecture and data management. By way of this concept, the tool-based solution detects and prevents interface and data inconsistencies not only during the software development process but throughout the lifecycle of the software product.
Turin, Raymond C.
Analyze This! Sound Static Analysis for Integration Verification of Large-Scale Automotive Software2019-01-12464/2/2019
Safety-critical embedded software has to satisfy stringent quality requirements. One such requirement, imposed by all contemporary safety standards, is that no critical run-time errors must occur. Runtime errors can be caused by undefined or unspecified behavior of the programming language; examples are buffer overflows or data races. They may cause erroneous or erratic behavior, induce system failures, and constitute security vulnerabilities. A sound static analyzer reports all such defects in the code, or proves their absence. Sound static program analysis is a verification technique recommended by ISO/FDIS 26262 for software unit verification and for the verification of software integration. In this article we propose an analysis methodology that has been implemented with the static analyzer Astrée. It supports quick turn-around times and gives highly precise whole-program results. We give an overview of the key concepts of Astrée that enable it to efficiently handle large-scale code, and describe a pre-analysis which transforms the source code to make it better amenable to static analysis. The experimental results confirm that sound static analysis can be successfully applied for integration verification of large-scale automotive software.
Kaestner, DanielSchmidt, BernardSchlund, MaximilianMauborgne, LaurentWilhelm, StephanFerdinand, Christian
Localization and Perception for Control and Decision-Making of a Low-Speed Autonomous Shuttle in a Campus Pilot Deployment12-01-02-000311/12/2018
Future SAE Level 4 and Level 5 autonomous vehicles (AV) will require novel applications of localization, perception, control, and artificial intelligence technology in order to offer innovative and disruptive solutions to current mobility problems. This article concentrates on low-speed autonomous shuttles that are transitioning from being tested in limited traffic, dedicated routes to being deployed as SAE Level 4 automated driving vehicles in urban environments like college campuses and outdoor shopping centers within smart cities. The Ohio State University has designated a small segment in an underserved area of the campus as an initial AV pilot test route for the deployment of low-speed autonomous shuttles. This article presents initial results of ongoing work on developing solutions to the localization and perception challenges of this planned pilot deployment. The article treats autonomous driving with Real-Time Kinematic (RTK) GPS (Global Positioning Systems) with an inertial measurement unit (IMU), combined with simultaneous localization and mapping (SLAM) with three-dimensional light detection and ranging (LIDAR) sensor, which provides solutions to scenarios where GPS is not available or a lower cost, and hence lower accuracy GPS is desirable. Our in-house automated low-speed electric vehicle is used in experimental evaluation and verification. In addition, the experimental vehicle has vehicle to everything (V2X) communication capability and utilizes a dedicated short-range communication (DSRC) modem. It is able to communicate with instrumented traffic lights and with pedestrians and bicyclists with DSRC-enabled smartphones. Before real-world experiments, our connected and automated driving hardware-in-the-loop (HiL) simulator with real DSRC modems is used for extensive testing of the algorithms and the low-level longitudinal and lateral controllers. Real-world experiments that are reported here have been conducted in a small test area close to the Ohio State University AV pilot test route. Model-in-the-loop simulation, HiL simulation, and experimental testing are used for demonstrating the feasibility and robustness of this approach to developing and evaluating low-speed autonomous shuttle localization and perception algorithms for control and decision-making.
Wen, BowenGelbal, Sukru YarenGuvenc, Bilin AksunGuvenc, Levent
Product Line Engineering for Basic Software of Automotive Embedded Systems2018-01-14574/3/2018
In the early 1980s, an oxygen sensor was applied to improve the fuel efficiency of automotive embedded systems. Currently, the complexity of software development has being increased due to the emergence of various requirements and the electronic control devices to ensure the safety and convenience of the driver. The high-performance hardware embedded in the ECU is a big issue for the automobile industry. OEMs, TIERs, tool providers, and the others are aiming at a variety of unit reusability, including software and hardware, based on the plug-and-play architecture concept. It is enhancing the quality attributes (safety, performance, real-time) of various perspectives. Furthermore, international standard process (ISO 26262, A-SPICE) does not provide a direct methodology for dealing with requirements refinement procedures, standard specification methods, and traceability of extracts. Although the area of the conventional basic software, which is the other area excluding the application in the entire software of the embedded system, was not subject to reuse unit in the past, the reusability of the basic software becomes important due to various backgrounds, including explosion, management of system variations. However, there is a lack of an efficient methodology for the reuse-based development process of the basic software throughout the international automotive industry. In this paper, we acquire and evaluate core assets through a feature-based product engineering approach to TCU, AWD, and SCU in HYUNDAI AUTRON Powertrain Control Systems. By introducing the application examples of new system development, we examine the effects of the basic software reusability.
Park, JoonhyunHan, SeonMi
Localization and Perception for Control and Decision Making of a Low Speed Autonomous Shuttle in a Campus Pilot Deployment2018-01-11824/3/2018
Future SAE Level 4 and Level 5 autonomous vehicles will require novel applications of localization, perception, control and artificial intelligence technology in order to offer innovative and disruptive solutions to current mobility problems. This paper concentrates on low speed autonomous shuttles that are transitioning from being tested in limited traffic, dedicated routes to being deployed as SAE Level 4 automated driving vehicles in urban environments like college campuses and outdoor shopping centers within smart cities. The Ohio State University has designated a small segment in an underserved area of campus as an initial autonomous vehicle (AV) pilot test route for the deployment of low speed autonomous shuttles. This paper presents initial results of ongoing work on developing solutions to the localization and perception challenges of this planned pilot deployment. The paper treats autonomous driving with real time kinematics GPS (Global Positioning Systems) with an inertial measurement unit (IMU), combined with simultaneous localization and mapping (SLAM) with three-dimensional light detection and ranging (LIDAR) sensor, which provides solutions to scenarios where GPS is not available or a lower cost and hence lower accuracy GPS is desirable. Our in-house automated low speed electric vehicle is used in experimental evaluation and verification. In addition, the experimental vehicle has vehicle to everything (V2X) communication capability and utilizes a dedicated short-range communication (DSRC) modem. It is able to communicate with instrumented traffic lights and with pedestrians and bicyclists with DSRC enabled smartphones. Before real-world experiments, our connected and automated driving hardware in the loop (HiL) simulator with real DSRC modems is used for extensive testing of the algorithms and the low level longitudinal and lateral controllers. Real-world experiments that are reported here have been conducted in a small test area close to the Ohio State University AV pilot test route. Model-in-the-loop simulation, HiL simulation and experimental testing are used for demonstrating the feasibility and robustness of this approach to developing and evaluating low speed autonomous shuttle localization and perception algorithms for control and decision making.
Wen, BowenGelbal, Sukru YarenAksun Guvenc, BilinGuvenc, Levent
Secure Deterministic L2/L3 Ethernet Networking for Integrated Architectures2017-01-21039/19/2017
Cybersecurity attacks exploit vulnerabilities related to the increased complexity and connectivity of critical infrastructure systems. This paper investigates the context and use of key security technologies, processes, challenges and use cases for the design of advanced integrated architectures with security, safety, and real-time performance considerations. In such architectures, deterministic Ethernet standards are used as a baseline for system integration in closed embedded systems or open mixed criticality systems. Security-informed safety development processes for integrated architectures are required to prevent catastrophic failures caused by environmental and cyber threats, due to expanding number of security vulnerabilities in complex and increasingly open systems. State-of-art safety/security processes for integrated systems in cross-industry environments are considered and similarities examined, for different types of integrated architectures. In integrated systems and IMA which share common resources, multi-level secure systems and composable modular architectures such as MILS based on separation kernels and ARINC653 API are gaining importance for design of safe and secure distributed applications with real-time performance requirements. Network security is a core component of the overall cyber-security and defense-in-depth capability for distributed architectures. Protection mechanism for information, interface and system integrity, communication availability, and data confidentiality are required for design of safe and secure integrated embedded infrastructure. In deterministic Ethernet networks with Time-Triggered Ethernet (SAE AS6802) and ARINC664 services can actively support security measures for mixed-criticality applications. The network partitioning, dataflow isolation, configuration protection, per-flow traffic policing, link and end-to-end encryptions or authentication, and internal network device partitioned architecture can be useful for design of open networked systems which can also accept previously unknown soft-time or bursty traffic, while hosting highly critical functions with temporal boundaries. After an overview of security issues in networks within integrated architectures, this paper continues with discussion of MACsec and IPsec mechanisms, packet firewalls, secure shells and Denial-Of-Service (DoS) protection mechanisms for secure and deterministic L2/L3 networking.
Hirschler, BerndJakovljevic, Mirko
Adopting Model-Based Software Design and Verification for Aerospace Systems2017-01-21109/19/2017
The complexity of software development is increasing unprecedentedly with every next generation of aircraft systems. This requires to adopt new techniques of software design and verification that could optimize the time and cost of software development. At the same time these techniques need to ensure high quality of software design and safety compliance to regulatory guidelines like DO-178C [1] and its supplements DO-330[2] and DO-331[3]. To arrive at new technologies one has to evaluate the alternate methods available for software design by developing models, integration of models, auto-code generation, auto test generation and also the performance parameters like time, effort, reuse and presentation needs to be evaluated. We have made an attempt to present summary of alternate design concept study, and edge of MBD over other design techniques. The new techniques have challenges in managing the software development processes through conventional means and showing their compliance to stringent industry standards and guidelines. We have present process compliance to aerospace software development guideline DO-178C. This paper has discussed requirements of DO-178C and its associated supplement DO-331 for model based software development and demonstrated means of compliance for models. It has also presented requirements of DO-330 for tool qualification and its applicability to model-based software development and verification.
Jha, Ashutosh KumarChoudhary, Prakash
Optimizing the Benefit of Virtual Testing with a Process-Oriented Approach2017-01-21149/19/2017
In the aerospace industry, methods for virtual testing cover an increasing range of test executions carried out during the development and test process of avionics systems. Over the last years, most companies have focused on questions regarding the evaluation and implementation of methods for virtual testing. However, it has become more and more important to seamlessly integrate virtual testing into the overall development process. For instance, a company’s test strategy might stipulate a combination of different methods, such as SIL and HIL simulation, in order to benefit from the advantages of both in the same test process. In this case, efforts concentrate on the optimization of the overall process, from test specification to test execution, as well as the test result evaluation and its alignment with methods for virtual testing. Furthermore, software tools have to be suitable for virtual testing and the entire tool chain has to be adaptable so it can be used for different test methods for various applications that have different users. This paper introduces an exemplary validation and verification process according to ARP4754A and describes how virtual testing contributes to a more efficient overall development process. The ARINC 653 software architecture serves as an example for demonstrating the benefits of using different virtual test environments. In order to coordinate and manage the design, implementation and test process, all test and simulation data is stored centrally using a data and test management tool that reduces complexity for an improved overview. Examples from real projects will illustrate this process-oriented approach.
Stavesand, Jann-EveReglitz, SörenHimmler, Andreas
Finding All Potential Run-Time Errors and Data Races in Automotive Software2017-01-00543/28/2017
Safety-critical embedded software has to satisfy stringent quality requirements. All contemporary safety standards require evidence that no data races and no critical run-time errors occur, such as invalid pointer accesses, buffer overflows, or arithmetic overflows. Such errors can cause software crashes, invalidate separation mechanisms in mixed-criticality software, and are a frequent cause of errors in concurrent and multi-core applications. The static analyzer Astrée has been extended to soundly and automatically analyze concurrent software. This novel extension employs a scalable abstraction which covers all possible thread interleavings, and reports all potential run-time errors, data races, deadlocks, and lock/unlock problems. When the analyzer does not report any alarm, the program is proven free from those classes of errors. Dedicated support for ARINC 653 and OSEK/AUTOSAR enables a fully automatic OS-aware analysis. In this article we give an overview of the key concepts of the concurrency analysis and report on experimental results obtained on concurrent automotive software. The experiments confirm that the novel analysis can be successfully applied to real automotive software projects.
Kaestner, DanielMiné, AntoineSchmidt, AndréHille, HeinzMauborgne, LaurentWilhelm, StephanRival, XavierFeret, JérômeCousot, PatrickFerdinand, Christian
Criteria-Driven Approach in Automotive Software Development – Integrating Concepts of Formal Methods with Testing *CSP Meta QA Testing* *CSP Meta QA Testing II* *CSP Meta QA Testing DEMO* *CSP Meta QA Testing - SM*2017-01-00033/28/2017
We propose a verification method in the field of automotive control systems integrating the concepts of Formal Methods with testing, aiming at efficient and reliable software development. Although Formal Methods are believed to provide the benefits of their rigorous nature and their inherent capability of automation, only limited cases are known where Formal Methods were applied in system and software development, in practice, due to two major difficulties: appropriate abstraction in modeling and scalability in automated reasoning. Focusing on testing on the other hand, there is the difficulty of selecting reasonable set of tests for given verification objectives. In order to overcome these difficulties, our approach is to present verification criteria for testing to appropriately cover the property with the help of the Formal Method concepts. From the consistency with respect to the abstraction level of models between generic property (such as controllability) and underlying assumptions, we derive test coverage that covers the models and the assumptions. Based on a case study using a set of the artifact of a product system, we propose a criteria-driven approach with potential benefits in that we expect to gain the practical efficiency of testing the automotive control systems with the concept of model-checking.
Tohdo, Tetsuya
Identifying Security Vulnerabilities Early in the ECU Software Development Lifecycle2017-01-16573/28/2017
In the past few years, automotive electronic control units (ECUs) have been the focus of many studies regarding the ability to affect the deterministic operation of safety critical cyber-physical systems. Researchers have been able to successfully demonstrate flaws in security design that have considerable, dramatic impacts on the functional safety of a target vehicle. With the rapid increase in data connectivity within a modern automobile, the attack surface has been greatly broadened to allow adversaries remote access to vehicle control system software and networks. This has serious implications, as a vast number of vulnerability disclosures released by security researchers point directly to common programming bugs and software quality issues as the root cause of successful exploits which can compromise the vehicle as a whole. In this paper, we aim to bring to light the most prominent categories of bugs found during the software development life cycle of an automotive ECU. We employ the method of static code analysis using reference coding standards such as MISRA and CERT C secure coding guidelines, to identify categories of software bugs which are most likely to remain in the vehicle, undetected as zero-day security vulnerabilities. We further examine the security issues originating from each category and provide an insight into the systematic elimination of crucial security-related bugs, much earlier in the software development life cycle. In the long term, we expect such an approach to drastically reduce the amount of attack vectors available for exploit in the ECU's software and limit the scope of damage possible by a malicious adversary.
Edwards, JesseKashani, Ameer
New Approach of Tools Application for Systems Engineering in Automotive Software Development2017-01-16013/28/2017
This paper outlines the modeling process in SysML (Systems Modeling Language) in context of MBSE (Model Based Software Engineering) as well as the MBD (Model-Based Design) in Simulink and we compare the models to get useful information into software. For this goal, we propose the use of an RM/SM tool (Requirements Management and Systems Modeling) (3SL Cradle) and Matlab/Simulink to model the system, do the system validations, and finally embed the generated code. For automotive systems, the development process is visualized through the V-Model, which leads to the right choice of components, the integration of the system and the project realization. The first step in V-Model handles the requirements management for the development, i.e., the requirements for a project will be collected in respect to the stakeholder’s needs and system limitations. Then, the next steps consist of modeling the system based on its requirements, going through simulation, system validation through Model-In-the-Loop (MIL), Software-In-the-Loop (SIL), Processor-In-the-Loop (PIL), and Hardware-In-the-Loop (HIL) tests. For this paper, the chosen modeling language was SysML for the MBSE point of view because it aims to standardize Modeling Design, by unifying diverse modeling languages used by engineers. This language also supports specification, analysis, design, verification, and validation of systems. To get executable models, we use Matlab/Simulink models that are largely used by the Original Equipment Manufacturers (OEMs) to develop new products. Our approach addresses the V-Model through SysML and MBD in Matlab/Simulink towards software validation. To achieve that, we use the commercial RM/SM tool that is used to collect stakeholder’s and system requirements. It provides a SysML design section as well where SysML models can be developed according to project requirements. One of the objectives in using the commercial tool is that it will be possible to analyze the transition from models in RM/SM tools to models for simulation, such as Simulink and offer a new possibility for OEM’s and suppliers to abstract system models into executable models. The main contribution of this paper is that the automotive software development process is showed from its concept to its realization in real systems.
Santos, Max MauroMendes, CelsoBanik, TaysaFranco, FelipeNeme, JoãoPrado, WanderleyCerri, FernandoNunes, Lauro
Arttest – a New Test Environment for Model-Based Software Development *CSP Meta QA Testing*2017-01-00043/28/2017
Modern vehicles become increasingly software intensive. Software development therefore is critical to the success of the manufacturer to develop state of the art technology. Standards like ISO 26262 recommend requirement-based verification and test cases that are derived from requirements analysis. Agile development uses continuous integration tests which rely on test automation and evaluation. All these drove the development of a new model-based software verification environment. Various aspects had to be taken into account: the test case specification needs to be easily comprehensible and flexible in order to allow testing of different functional variants. The test environment should support different use cases like open-loop or closed-loop testing and has to provide corresponding evaluation methods for continuously changing as well as for discrete signals. In a joint project of RWTH Aachen University and Ford, a new tool, Arttest, has been developed for testing model-based software. The tool uses a domain specific language to specify the tests. It offers different test evaluation methods for automated open- and closed-loop testing and reactive testing. It automatically executes the tests, evaluates the outputs and generates summary reports indicating passed tests and errors found. The paper presents the tool and its various unique propositions such as domain specific test language, the evaluation properties and other features like open-loop and closed-loop capabilities.
Wiechowski, NorbertRambow, ThomasBusch, RainerKugler, AlexanderHansen, NormanKowalewski, Stefan
Hardware-in-the-Loop Pneumatic Braking System for Heavy Truck Testing of Advanced Electronic Safety Interventions2016-01-16484/5/2016
The rapid innovation underway with vehicle brake safety systems leads to extensive evaluation and testing by system developers and regulatory agencies. The ability to evaluate complex heavy truck braking systems is potentially more rapid and economical through hardware-in-the-loop (HiL) simulation which employs the actual electronics and vehicle hardware. Though the initial HiL system development is time consuming and expensive, tests conducted on the completed system do not require track time, fuel, vehicle maintenance, or technician labor for driving or truck configuration changes. Truck and trailer configuration and loading as well as test scenarios can be rapidly adjusted within the vehicle dynamics simulation software to evaluate the performance of automated safety interventions (such as ESC) over a wide range of conditions. Hardware-in-the-loop simulation does not obviate the need for all track testing; vehicle models for simulation must be validated against track data for each truck platform. But HiL simulation can supplement and extend track data for tests at higher speeds, low friction surfaces, and alternate vehicle configurations. A HiL pneumatic braking system was developed for this purpose by the National Highway Traffic Safety Administration, with the goal of evaluating performance as it relates to safety. This paper describes the system in detail and includes some sample results of the testing.
Salaani, M. KamelRao, SughoshEvery, Joshua L.Mikesell, David R.Barickman, FrankElsasser, DevinMartin, John
Guaranteed Timing Behavior Begins with an Established Ethernet Backbone2016-01-00614/5/2016
Increasingly, Ethernet is being used in automotive as a vehicle network backbone. It is ideal for service-oriented communications; streamed communications, such as Audio/Video Bridging (AVB) [1]; and Diagnostics over Internet Protocol (DoIP) [2] communications - areas in which high-bandwidth and reliable performance are essential. Designers are accustomed to network communication systems CAN, LIN, and FlexRay, but how will the timing performance be verified in an Ethernet network? This paper looks at network-wide timing analysis challenges where a mixture of CAN, FlexRay, and Ethernetbased busses co-exist. It is also worth noting that the AUTOSAR standard [3] supports timing definition for all elements in a mixed topology network, but again, accounting for the many different timing paths is a non-trivial process. Figure 1 The Ethernet backbone serving different domains. Due to features are distributed in the vehicle, the communication need is typically tightly related to the feature complexity. Also different features have also requirements of isolation from other features, for example infotainment communication may need to be isolated from dynamic chassis control. One efficient way to design the topology in the vehicle is to have a backbone with different domain sub-networks (Figure 1). This allows the designer to isolate different domains and keep control over the communication.
Kallerdahl, AndersSalah, Mohammad
Simultaneous Estimation of the SOC and Parameters of Batteries for HEV/EV2016-01-11954/5/2016
This paper proposes a battery state estimation on a battery management system (BMS) for hybrid electric vehicles (HEVs) and electric vehicles (EVs). It is important to estimate a state of charge (SOC) and parameters of the battery such as a state of health (SOH), internal resistances and dynamics of electrochemical reactions. The BMS can provide information on the driving range of the EVs to the drivers by accurately estimating SOC and SOH. It can also calculate a state of power (SOP) to use the battery safely by accurately estimated SOC, internal resistances and others. For that purpose, this paper proposes the BMS adopted a simultaneous state of charge (SOC) and parameter estimation method using log-normalized unscented Kalman filter (LnUKF). The key idea is a lognormalization of the parameters to improve numerical stability and robustness of the algorithm. The proposed system is verified by a series of simulations using experimental data with EVs. One of the SOC and parameter estimation results is for low temperature data on the chassis dynamometer. The proposed system can accurately estimate SOC and parameters of the battery without relying on the experimentally obtained data even if it is under the harsh conditions such as low temperature environment. As a result, it can accurately estimate SOH and SOP of the battery since they are estimated by using estimates of SOC and parameters of the battery.
Baba, AtsushiItabashi, KinnosukeTeranishi, NozomuEdamoto, YoshihiroOsamura, KensukeMaruta, IchiroAdachi, Shuichi
Platform-Based Automotive Safety Features2016-01-01364/5/2016
Optional software-based features (for example, to provide active safety, infotainment, etc.) are increasingly becoming a significant cost driver in automotive systems. In state-of-the-art production techniques, these optional features are built into the vehicle during assembly. This does not give the customer the flexibility to choose the specific set of features as per their requirement. They either have to buy a pre-bundled option that may or may not satisfy their preferences or are unable to find an exact combination of features from the inventory provided by a dealership. Alternatively, they have to pre-order a car from the manufacturer, which could result in a substantial delay. Therefore, it is important to improve the flexibility of delivering the optional features to customers. Towards this objective, the vehicle could be configured with the desired options at the dealership, when the customer requires them. Going a bit further, it would be desirable to allow a car to be configured according to changes in customer needs in a post-market environment and according to manufacturer specifications. This new paradigm of delivering options would require a change in the way automotive software is architected and deployed. In this paper, we present a vision that describes a new way to deploy automotive safety features and ensuring their correct execution without interference. This vision is based on the concept of a platform. The high level functionality of this platform is to provide an interface that enables the deployment of new features on the platform and perform admission control to make sure that sufficient resources are allocated for these features. Additionally, the platform should also guarantee isolation of the new features from already deployed features.
Gangadharan, DeepakSokolsky, OlegLee, InsupKim, BaekGyuLin, Chung-WeiShiraishi, Shinichi
A Generic Fault Maturing and Clearing Strategy for Continuous On-Board Diagnostic Monitoring2016-01-06334/5/2016
Per California Air Resources Board (CARB) regulations, On-board diagnostic (OBD) of vehicle powertrain systems are required to continuously monitor key powertrain components, such as the circuit discontinuity of actuators, various circuit faults of sensors, and out-of-range faults of sensors. The maturing and clearing of these continuous monitoring faults are critical to simplification of algorithm design, save of engineering cost (i.e., calibration), and reduction of warranty issues. Due to the nature of sensors (to sense different physical quantities) and actuators (to output energy in desired ways), most of OEM and supplies tend to choose different fault maturing and clearing strategy for sensors and actuators with different physics nature, such as timer-based, counter-based, and other physical-quantity-based strategies. Such choice brings substantial inconvenience and incurs large engineering cost for automotive manufacturers, because more and more sensors are replaced by smaller and smarter sensors that have different physics nature while achieving the same sensing functionality. It is, hence, desired to have a generic fault maturing and clearing strategy to commonize the handling of different sensors and actuators, to simplify the transition to a new hardware configuration, to provide fast and accurate maturing approach, and to smoothly handle smart sensors/actuators. This research proposed a generic fault maturing and clearing strategy to achieve the above objectives by utilizing unitless indices to mature and clear faults, standardizing the inputs and outputs, and improving compatibility with multiple designer-input options.
Guo, Yichao
Taxonomy of Automotive Real-Time Scheduling2016-01-00384/5/2016
Automobiles are getting more and more sophisticated with increased demand for more comfort and safety by customers. Due to this, the automotive Electronic Control Units (ECU) and the software applications running on these ECUs have become more complex and computationally more intensive. This has resulted in Original Equipment Manufacturers (OEMs) migrating to multicore platforms. Optimal usage of multicore platform necessitates the design of new scheduling algorithms. In the past decade, different approaches to implement hard real time scheduling in automotive domain have been proposed for single core as well as multicore architectures. We explore different scheduling techniques proposed so far which are relevant to automotive domain and also, provide a taxonomy of these scheduling algorithms, which will help the automotive design engineer to make an informed decision. Through this study it is realized that, automotive standards such as AUTOSAR use manual scheduling, which consume lot of time to develop a schedule table and are inflexible. To address this issue, a new mathematical scheduling approach has been discussed as a case study. This systematic approach will not only reduce the time taken to develop a schedule table, it will also predict schedulability of a given set of tasks. The schedulability will be in terms of task overlaps and deadline misses which can be analyzed at design phase and is also more flexible by providing the users with multiple options based on earliest start time, least utilization and least task overlap criteria, along with the possibility of producing optimal results.
Ranadive, PritiSengupta, SomnathKumar, NarendraBoggarapu, NaveenVaidya, Vinay
Architectural Concepts for Fail-Operational Automotive Systems2016-01-01314/5/2016
The trend towards even more sophisticated driver assistance systems and growing automation of driving sets new requirements for the robustness and availability of the involved automotive systems. In case of an error, today it is still sufficient that safety related systems just fail safe or silent to prevent safety related influence of the driving stability resulting in a functional deactivation. But the reliance on passive mechanical fallbacks in which the human driver taking over control, being inevitable in such a scenario, is expected to get more and more insufficient along with a rising degree of driving automation as the driver will be given longer reaction time. The advantage of highly or even fully automated driving is that the driver can focus on other tasks than controlling the car and monitoring it’s behavior and environment. Hence, it can no longer be expected that the driver will take over control of the vehicle quickly in case of a failure and taking into account the idea of a driverless car, this option might get even completely dispensable. This raises dramatically the requirements for availability and robustness of the involved car systems. Here the capability to provide functionality even in case of an error or defect is in focus inducing demand for a certain degree of redundancy. Currently this redundancy is quite often implemented by physical duplication of hardware and the involved software, leading to higher hardware costs, weight and energy consumption and finally also negatively impacting fuel efficiency. In this paper we will point out how an optimized fail operational approach can be realized. We also present different concepts for an implementation and identify deficits in the design and implementation of today’s automotive Electronic Control Units (ECUs), involved semiconductor products and software approaches. This is where we expect the main challenges to realize an optimized redundancy, especially for X-by-Wire systems. The hardware architecture of semiconductors as well as the applied software architecture on ECUs must be designed accordingly in order to reach smarter solutions.
Kohn, AndreSchneider, RolfVilela, AntonioRoger, AndreDannebaum, Udo
Items per page:
1 – 50 of 263